Currently configuring SAP Cloud Platform Trust settings (for a sub-account) but cannot get the group assertion attributes to come through automatically. I can see the AD groups come through in the SAML trace however the correct security role is not being assigned. Additionally, when we configure additional group settings in ADFS I get the following error which basically stops access to all services in the sub-account which is really annoying.